System and method for processing secret sharing authentication
Abstract
Disclosed herein is a system for a secret sharing authentication. The system may include a secret sharing information management server, a client device, and a network device. The secret sharing information management server may store and manage an authentication key capable of being used for secret sharing authentication, by dividing the authentication key into a first secret sharing key shard and a second secret sharing key shard, and allocate the first and second secret sharing key shards. The client device may receive the first secret sharing key shard from the secret sharing information management server and construct an interest packet by using the first secret sharing key shards. The network device may receive the second secret sharing key shard from the secret sharing information management server, and process the interest packet received from the client device on the basis of an ICN(Information Centric Networking) method by performing secret sharing authentication using the second secret sharing key shard and the first secret sharing key shard comprised in the interest packet.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system for a secret sharing authentication comprising:
a secret sharing information management server configured to store and manage a secret key capable of being used for secret sharing authentication by dividing the secret key into a first secret sharing key shard and a second secret sharing key shard, and to allocate the first and second secret sharing key shards; a client device configured to receive and manage the first secret sharing key shard allocated from the secret sharing information management server and to construct an interest packet by using the first secret sharing key shard; and a network device configured to receive and manage the second secret sharing key shard allocated from the secret sharing information management server, to process the interest packet received from the client device on the basis of an ICN (Information Centric Networking) method, and to perform secret sharing authentication by using the second secret sharing key shard and the first secret sharing key shard comprised in the interest packet.
2 . The system of claim 1 ,
wherein the client device generates a secret sharing authentication token comprised in the interest packet, and wherein the secret sharing authentication token comprises at least one of a hash algorithm identifier, a secret sharing ID necessary for authenticating the client device, the first secret sharing key shard, an integrity verification and encryption key, a request processing device path, and a code for verifying the integrity of the secret sharing authentication token.
3 . The system of claim 1 ,
wherein the network device executes authentication by checking the first secret sharing key shard comprised in the secret sharing authentication token, by estimating the first secret sharing key shard through a validation parameter, and by comparing the estimated first secret sharing key shard and the first secret sharing key shard comprised in the secret sharing authentication token.
4 . The system of claim 4 ,
wherein the network device constructs t threshold secret sharing key shards by merging the authenticated first secret sharing key shard and the (t-1) second secret sharing key shards that are initially set.
5 . The system of claim 4 ,
wherein the network device reconstructs a threshold sharing secret key through interpolation using the t threshold secret sharing key shards and verifies the threshold sharing secret key by comparing a secret key received from the secret sharing information management server and the reconstructed secret key.
6 . The system of claim 5 ,
wherein the network device extracts an integrity verification and encryption key comprised in the secret sharing authentication token and a first integrity verification code, generates a second integrity verification code by using the integrity verification and encryption key, and verifies the secret sharing authentication token by comparing the first integrity verification code and the second integrity verification code.
7 . The system of claim 2 ,
wherein the network device comprises a first network device and a second network device, and wherein the first network device requests split processing of a calculation function to the second network device.
8 . The system of claim 7 ,
wherein the first network device constructs a secret sharing authentication token for split processing and generates the interest packet comprising the secret sharing authentication token for split processing.
9 . The system of claim 8 ,
wherein the secret sharing authentication token for split processing comprises a secret sharing ID necessary for authenticating the client device, the first secret sharing key shard, an auxiliary integrity verification and encryption key generated by the first network device, and an auxiliary integrity verification code generated by the auxiliary integrity verification and encryption key.
10 . The system of claim 8 ,
wherein, in response to the receipt of the interest packet from the network device, the second network device processes the calculation function on the basis of information comprised in the interest packet, generates a response data packet comprising the processed calculation result, and transmits the generated response data packet to the first network device.
11 . The system of claim 10 ,
wherein the second network device encrypts the calculation result by using a secret key stored in the second network device.
12 . The system of claim 1 ,
wherein the secret sharing information management server sets a server parameter necessary for performing split authentication, and wherein the server parameter comprises at least one of an arbitrary random value for masking the secret sharing key shard, a multiplier group generator of field, a modulo operation decimal value, a masking parameter of the secret sharing key shard, and a validation parameter of the secret sharing key shard.
13 . The system of claim 1 ,
wherein the secret sharing information management server receives a registration request packet from the client device, performs verification for a signature of the registration request packet, processes registration by checking identification information of the client device, allocates the secret sharing key shard from an available secret sharing information pool of the client device, encrypts the secret sharing key shard into a public key of the client device, and constructs the encrypted data into a response packet signed with a secret key of the secret sharing information management server.
14 . The system of claim 1 ,
wherein the secret sharing information management server receives a registration request packet from the network device, performs verification for a signature of the registration request packet, processes registration by checking identification information of the network device, allocates the secret sharing key shard from an available secret sharing information pool of the network device, encrypts the secret sharing key shard into a public key of the network device, and constructs the encrypted data into a response packet signed with a secret key of the secret sharing information management server.
15 . The system of claim 1 ,
wherein the network device transmits a service registration request packet to the secret sharing information management server, receives a response packet from the secret sharing information management server, verifies a signature of the response packet by using a certificate of the secret sharing information management server, decodes the response packet by using a secret key of the network device, and checks and stores a secret sharing key shard of the network device and an initial verifier setting parameter comprised in the response packet.
16 . The system of claim 15 ,
wherein, based on t secret sharing key shards obtained by dividing a secret key, the initial setting parameter comprises at least one among (t-1) secret sharing key shard sets, calculations of (t- 2 ) Lagrange interpolation coefficients, and calculations of (t-1) Lagrange interpolation coefficients comprising the network device.
17 . A method for a secret sharing authentication, the method comprising;
masking, by a secret sharing information management server configured to split and manage a secret key used for secret sharing authentication, a first secret sharing key shard and providing the first secret sharing key shard to a client device and providing a second secret sharing key shard to a network device, constructing, by the client device, an interest packet by using the first secret sharing key shard and transmitting the interest packet to the network device based on an information centric networking (ICN) method, and processing, by the network device, the interest packet based on the ICN method by unmasking the first secret sharing key shard comprised in the interest packet, and by performing secret sharing authentication by using the unmasked first secret sharing key shards and the second secret sharing key shard.
18 . The method of claim 17 ,
wherein the transmitting of the interest packet to the network device comprises generating a secret sharing authentication token comprised in the interest packet, wherein the secret sharing authentication token comprises at least one among a hash algorithm identifier, a secret sharing ID necessary for authenticating the client device, the first secret sharing key shard, an integrity verification and encryption key, a request processing device path, and a code for verifying the integrity of the secret sharing authentication token.
19 . The method of claim 17 ,
wherein the performing of secret sharing authentication comprises: determining the first secret sharing key shard comprised in the secret sharing authentication token, estimating the first secret sharing key shard by using a validation parameter, and comparing the estimated first secret sharing key shard and the first secret sharing key shard comprised in the secret sharing authentication token.Join the waitlist — get patent alerts
Track US2021167947A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.